2026年全球威胁报告_58页_15mb
报告摘要
2026 Global Threat Report Summary
Core Content
The 2026 Global Threat Report by CrowdStrike highlights the evolving nature of cyber threats in the agentic era, where artificial intelligence (AI) is increasingly used by adversaries to enhance and accelerate their operations. The report emphasizes that speed, legitimacy, and low-visibility access paths are now the defining characteristics of evasive adversaries.
Main Points
-
AI Integration in Cyber Threats:
Adversaries are leveraging AI to improve their social engineering, information operations (IO), and technical operations. AI enables faster attack execution, more sophisticated deception, and the creation of convincing content and personas. -
Rise in Evasive Techniques:
The average eCrime breakout time dropped to 29 minutes in 2025, a 65% increase in speed from the prior year. The fastest breakout occurred in 27 seconds. Adversaries are moving laterally through trusted systems, cloud environments, and unmanaged devices, often without using malware. -
Malware-Free Intrusions:
82% of detections in 2025 were malware-free, showing that attackers are increasingly using authorized access paths and trusted identity flows to remain undetected. -
Supply Chain Exploitation:
Adversaries are targeting supply chain partners, SaaS platforms, and public code repositories to gain stealthy access. PRESSURE CHOLLIMA executed the largest single financial theft in 2025 by using Trojanized software delivered through a supply chain compromise. -
China-Nexus Activity:
China-nexus adversaries saw a 38% increase in targeted intrusion activity, with a 85% increase in logistics and telecom sectors. 67% of the vulnerabilities they exploited in 2025 were RCE flaws, allowing immediate system access. 40% of these attacks targeted internet-facing edge devices. -
Cloud and Identity Threats:
Cloud-conscious intrusions increased by 37%, with a 266% rise among state-nexus threat actors. Valid account abuse accounted for 35% of cloud incidents, showing the growing importance of identity security. -
Zero-Day Exploitation:
There was a 42% increase in the number of zero-day vulnerabilities exploited before public disclosure, underscoring the speed and proactivity of modern adversaries. -
Interactive Intrusions:
Adversaries are favoring interactive intrusions, where they engage directly with victim environments using legitimate credentials and native tools. These intrusions are harder to detect and contain due to their resemblance to authorized activity. -
eCrime Trends:
The CrowdStrike eCrime Index (ECX) showed a decline in early 2025, but reversed in the second half due to increased spam, vulnerability disclosures, and ransomware victims. Cryptocurrency price increases also amplified eCrime activity.
Key Adversary Themes
AI-Enabled Adversaries
- AI Adoption: Adversaries are increasingly using AI tools like ChatGPT, Gemini, Claude, and Grok to enhance their operations.
- AI Usage: AI is used for phishing, malware development, exploit generation, and social engineering.
- Impact: AI-enabled adversaries saw an 89% increase in attacks compared to 2024, with 82% of attacks being malware-free.
Ransomware and Cross-Domain Attacks
- Ransomware Expansion: Ransomware adversaries are moving across domains, using cloud and edge infrastructure for lateral movement and data exfiltration.
- Examples: CHATTY SPIDER exfiltrated data within four minutes of initial access, and FUNKLOCKER and RALORD shared encryption flaws from WormGPT-generated templates.
China-Nexus Threat Actors
- Activity Increase: China-nexus adversaries saw a 38% increase in intrusion activity, with a 85% rise in logistics and telecom.
- Targeting Edge Devices: 67% of the vulnerabilities they exploited were RCE flaws, targeting internet-facing edge devices like VPNs, firewalls, and gateways.
Supply Chain Attacks
- Supply Chain Exploitation: Adversaries are compromising upstream providers, development ecosystems, and code repositories to gain stealthy access.
- Notable Attack: PRESSURE CHOLLIMA executed a $1.46 billion USD cryptocurrency theft through Trojanized software.
Zero-Day Exploitation
- Zero-Day Rise: There was a 42% increase in the number of zero-day vulnerabilities exploited before public disclosure.
- Rapid Weaponization: Newly disclosed vulnerabilities were weaponized within days, compressing the time between discovery and exploitation.
Cloud and Identity Threats
- Cloud Access: Adversaries are exploiting cloud environments and hybrid identity systems for privileged access.
- Identity as a Target: Valid account abuse is a major vector, with 35% of cloud incidents involving this method.
CrowdStrike's Response
- Platform Innovation: CrowdStrike's Falcon® platform uses AI and trillions of telemetry events to detect and disrupt evasive adversaries.
- Counter Adversary Operations: This initiative combines threat intelligence, managed threat hunting, and AI-powered analysis to detect and stop evasive threats.
- Adversary OverWatch™: CrowdStrike expanded managed threat hunting to third-party SIEM data, enhancing visibility across the entire attack surface.
- Threat Intelligence Tools: Features like personalized views, organization-specific context, and the Threat Intelligence Browser Extension help security teams act with speed and confidence.
Conclusion
The 2025 threat landscape is defined by speed, legitimacy, and low-visibility access paths. Adversaries are increasingly using AI to enhance their operations, social engineering, and information campaigns. CrowdStrike's Counter Adversary Operations and Falcon® platform are critical in detecting, disrupting, and stopping these evasive threats. The report serves as a guide for defenders to understand and prepare for the evolving threat environment.
试读结束,高清完整版pdf/doc/ppt,请点下载